Threat Intelligence Team. (2021, August 23). New variant of Konni malware used in campaign targetting Russia. Retrieved January 5, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareKONNI | KONNI has stored collected information and discovered processes in a tmp file. |
| T1027.013 Encrypted/Encoded File |
MalwareKONNI | KONNI is heavily obfuscated and includes encrypted configuration files. |
| T1036.004 Masquerade Task or Service |
MalwareKONNI | KONNI has pretended to be the xmlProv Network Provisioning service. |
| T1041 Exfiltration Over C2 Channel |
MalwareKONNI | KONNI has sent data and files to its C2 server. |
| T1049 System Network Connections Discovery |
MalwareKONNI | KONNI has used |
| T1057 Process Discovery |
MalwareKONNI | KONNI has used the command |
| T1059.001 PowerShell |
MalwareKONNI | KONNI used PowerShell to download and execute a specific 64-bit version of the malware. |
| T1059.003 Windows Command Shell |
MalwareKONNI | KONNI has used cmd.exe to execute arbitrary commands on the infected host across different stages of the infection chain. |
| T1059.007 JavaScript |
MalwareKONNI | KONNI has executed malicious JavaScript code. |
| T1071.001 Web Protocols |
MalwareKONNI | KONNI has used HTTP POST for C2. |
| T1082 System Information Discovery |
MalwareKONNI | KONNI can gather the OS version, architecture information, hostname, and RAM size information from the victim’s machine and has used |
| T1105 Ingress Tool Transfer |
MalwareKONNI | KONNI can download files and execute them on the victim’s machine. |
| T1106 Native API |
MalwareKONNI | KONNI has hardcoded API calls within its functions to use on the victim's machine. |
| T1112 Modify Registry |
MalwareKONNI | KONNI has modified registry keys of ComSysApp, Svchost, and xmlProv on the machine to gain persistence. |
| T1134.002 Create Process with Token |
MalwareKONNI | KONNI has duplicated the token of a high integrity process to spawn an instance of cmd.exe under an impersonated user. |
| T1134.004 Parent PID Spoofing |
MalwareKONNI | KONNI has used parent PID spoofing to spawn a new `cmd` process using `CreateProcessW` and a handle to `Taskmgr.exe`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKONNI | KONNI has used certutil to download and decode base64 encoded strings and has also devoted a custom section to performing all the components of the deobfuscation process. |
| T1204.002 Malicious File |
MalwareKONNI | KONNI has relied on a victim to enable malicious macros within an attachment delivered via email. |
| T1218.011 Rundll32 |
MalwareKONNI | KONNI has used Rundll32 to execute its loader for privilege escalation purposes. |
| T1543.003 Windows Service |
MalwareKONNI | KONNI has registered itself as a service using its export function. |
| T1548.002 Bypass User Account Control |
MalwareKONNI | KONNI has bypassed UAC by performing token impersonation as well as an RPC-based method, this included bypassing UAC set to “AlwaysNotify". |
| T1560 Archive Collected Data |
MalwareKONNI | KONNI has encrypted data and files prior to exfiltration. |
| T1566.001 Spearphishing Attachment |
MalwareKONNI | KONNI has been delivered via spearphishing campaigns through a malicious Word document. |
| T1680 Local Storage Discovery |
MalwareKONNI | KONNI can gather information on connected drives and disk space from the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.